CVE-2016-5191Cross-site Scripting in Google Chrome

Severity
6.1MEDIUMNVD
EPSS
0.4%
top 39.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 18
Latest updateMay 14

Description

Bookmark handling in Google Chrome prior to 54.0.2840.59 for Windows, Mac, and Linux; 54.0.2840.85 for Android had insufficient validation of supplied data, which allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via crafted HTML pages, as demonstrated by an interpretation conflict between userinfo and scheme in an http://javascript:[email protected] URL.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 2.8 | Impact: 2.7

Affected Packages1 packages

NVDgoogle/chrome53.0.2785.143

🔴Vulnerability Details

2
GHSA
GHSA-4rf5-qf66-5m85: Bookmark handling in Google Chrome prior to 542022-05-14
OSV
CVE-2016-5191: Bookmark handling in Google Chrome prior to 542016-12-18

📋Vendor Advisories

1
Red Hat
chromium-browser: universal xss in bookmarks2016-10-12

💬Community

2
Bugzilla
CVE-2016-5191 chromium-browser: universal xss in bookmarks2016-10-13
Bugzilla
CVE-2016-5181 CVE-2016-5182 CVE-2016-5183 CVE-2016-5184 CVE-2016-5185 CVE-2016-5186 CVE-2016-5187 CVE-2016-5188 CVE-2016-5189 CVE-2016-5190 CVE-2016-5191 CVE-2016-5192 CVE-2016-5193 CVE-2016-5194 chro2016-10-13